ISO 27001 Annex A 5.9 focuses on maintaining an inventory of information and other assets that are associated with information processing.
The purpose is to help the organization understand:
- What information it owns or manages
- What systems process that information
- What devices and technology support those systems
- Who is responsible for the assets
- Where important information and assets are located
- Which assets are critical to the business
- What needs to be protected
Simple explanation
A.5.9 means an organization should know what information and technology assets it has, where they are, who is responsible for them, and what needs to be protected.
You cannot effectively protect assets that you do not know exist.
For example, if a company does not know that an employee has created a production database outside the approved environment, the organization may not be able to properly secure or monitor it.
Why is A.5.9 important?
Modern organizations may have hundreds or thousands of assets.
These may include:
- Laptops
- Servers
- Cloud resources
- Databases
- Applications
- Source-code repositories
- SaaS applications
- Mobile devices
- Network equipment
- APIs
- Digital documents
- Customer information
- Employee information
- Credentials and secrets
- Backup systems
Without an accurate inventory, organizations may:
- Forget to patch systems
- Leave accounts active
- Miss vulnerabilities
- Lose track of sensitive information
- Fail to apply appropriate security controls
- Have difficulty responding to incidents
- Lose track of third-party services
- Fail to meet customer or regulatory requirements
Simple principle
Know what you have before you try to protect it.
What does A.5.9 require?
The organization should establish and maintain an inventory of information and other associated assets.
The inventory should be:
- Appropriate to the organization’s environment
- Maintained and updated
- Assigned to responsible owners
- Relevant to information security
- Available to appropriate personnel
The exact format is not prescribed.
An organization may use:
- Spreadsheet
- CMDB
- Asset-management software
- GRC platform
- Cloud inventory
- IT management platform
- Configuration-management database
The important point is that the organization can demonstrate that relevant assets are identified and managed.
What is an Information Asset?
Information assets include information that has value to the organization.
Examples:
Business information
- Business plans
- Contracts
- Financial information
- Management reports
- Intellectual property
Customer information
- Customer records
- Customer contracts
- Customer support information
- Customer data
Personal information
- Employee information
- Customer personal data
- Contact information
- Identification information
Security information
- Security logs
- Vulnerability reports
- Incident records
- Risk assessments
- Security configurations
Technical information
- Source code
- API documentation
- Architecture diagrams
- Configuration files
- Technical documentation
What are Associated Assets?
Associated assets are assets that support information processing.
Examples include:
Hardware
- Laptops
- Desktops
- Servers
- Mobile devices
- Network devices
Software
- Operating systems
- Applications
- Databases
- Development tools
- Security tools
Cloud
- AWS accounts
- Azure subscriptions
- GCP projects
- Cloud databases
- Storage buckets
- Virtual machines
- Containers
Applications and services
- CRM
- HRMS
- ERP
- Ticketing systems
- Collaboration platforms
- SaaS applications
Network and infrastructure
- Firewalls
- Routers
- Switches
- VPN
- DNS
- Load balancers
Digital repositories
- GitHub repositories
- Document storage
- Shared drives
- Backup systems
Activities required to implement A.5.9
1. Identify information assets
Start by identifying important information used by the organization.
For example:
| Information Asset | Example |
|---|---|
| Customer Information | Customer account data |
| Employee Information | HR records |
| Financial Information | Invoices and financial records |
| Source Code | GitHub repositories |
| Security Information | Incident reports |
| Business Information | Contracts |
| Product Information | Product documentation |
2. Identify associated technology assets
Next identify the systems and technology used to create, store, process or transmit that information.
Example
Customer Information
↓
Stored in:
Production Database
↓
Hosted on:
AWS
↓
Accessed through:
Customer Application
↓
Managed by:
Engineering Team
This relationship helps the organization understand what needs to be protected.
3. Assign an owner
Each important asset should have an appropriate owner.
The owner does not necessarily need to operate the asset.
The owner is responsible for ensuring that appropriate security requirements are applied.
For example:
| Asset | Owner |
|---|---|
| Customer Database | CTO |
| HR Information | HR Manager |
| Financial Information | CFO |
| Source Code | Engineering Lead |
| AWS Environment | Cloud/IT Lead |
| Security Logs | Security Lead |
For a startup, one person may own multiple assets.
4. Classify information
The organization should classify information according to its sensitivity and business value.
For example:
Public
Information intended for public release.
Examples:
- Website content
- Marketing material
- Public documentation
Internal
Information intended for employees or authorized personnel.
Examples:
- Internal procedures
- Internal announcements
- Operational documentation
Confidential
Information that could cause harm if disclosed without authorization.
Examples:
- Customer contracts
- Business plans
- Internal financial information
Restricted
Highly sensitive information requiring stronger protection.
Examples:
- Credentials
- Encryption keys
- Sensitive personal information
- Critical security information
The organization’s classification scheme can be simpler or more detailed depending on its needs.
5. Record important asset attributes
The inventory should contain information that is useful for managing security.
Depending on the organization, this may include:
- Asset name
- Asset type
- Owner
- Location
- Business purpose
- Classification
- Criticality
- System/environment
- Responsible department
- Vendor
- Lifecycle status
- Associated information
- Access requirements
Not every field is required for every organization.
The inventory should be practical and useful.
6. Identify critical assets
Not every asset has the same importance.
The organization should identify assets that are critical to:
- Business operations
- Customer services
- Security
- Regulatory compliance
- Revenue generation
- Confidential information
Example
For a SaaS company:
Production Database → Critical
Production Application → Critical
Source Code Repository → High
Corporate Website → Medium
Marketing Presentation → Low
This can help prioritize security efforts.
7. Include cloud assets
Modern organizations often have significant assets in cloud environments.
The inventory may include:
- Cloud accounts
- Subscriptions
- Projects
- Virtual machines
- Databases
- Storage
- Containers
- Kubernetes clusters
- Serverless functions
- API gateways
- Security services
Example
A startup may maintain:
| Cloud Asset | Environment | Owner | Criticality |
|---|---|---|---|
| AWS Production Account | Production | CTO | Critical |
| PostgreSQL Database | Production | Engineering | Critical |
| S3 Storage | Production | Engineering | High |
| Development Account | Development | Engineering | Medium |
8. Include SaaS applications
SaaS applications are frequently forgotten in asset inventories.
Examples:
- Microsoft 365
- Google Workspace
- Slack
- Jira
- GitHub
- Salesforce
- HubSpot
- Zoom
- HR platforms
- Accounting platforms
The organization should understand:
- Who owns the application?
- What information does it contain?
- Who can access it?
- Is sensitive information stored there?
- What security requirements apply?
9. Keep the inventory updated
An inventory that is created once and never updated will quickly become inaccurate.
The organization should establish events that trigger updates.
Examples:
- New application
- New cloud environment
- New employee
- New laptop
- New SaaS provider
- System retirement
- Business acquisition
- Major technology change
- New database
- New production environment
10. Periodically review the inventory
The organization should periodically confirm:
- Assets still exist
- Owners are correct
- Classification remains appropriate
- Criticality remains appropriate
- Retired assets are removed
- New assets are included
- Unauthorized assets are investigated
The frequency should be based on the organization’s environment and risk.
Startup Example
Consider a SaaS startup with 50 employees.
The company uses:
- AWS
- GitHub
- Google Workspace
- Slack
- Jira
- PostgreSQL
- Microsoft 365 for some business functions
- Several third-party SaaS applications
A simple asset inventory could look like:
| Asset | Type | Owner | Classification | Criticality |
|---|---|---|---|---|
| AWS Production | Cloud | CTO | Confidential | Critical |
| Customer Database | Information/Database | CTO | Restricted | Critical |
| GitHub Organization | SaaS/Repository | Engineering Lead | Confidential | Critical |
| Google Workspace | SaaS | IT Lead | Confidential | High |
| Jira | SaaS | Engineering | Internal | High |
| Employee Laptops | Hardware | IT | Confidential | High |
| Corporate Website | Application | Marketing/IT | Public | Medium |
This gives the organization a practical picture of its environment.
Asset Lifecycle
Assets should be managed throughout their lifecycle.
1. Acquisition
New asset identified
↓
2. Registration
Added to inventory
↓
3. Ownership
Owner assigned
↓
4. Classification
Information sensitivity determined
↓
5. Protection
Security controls applied
↓
6. Review
Asset periodically reviewed
↓
7. Retirement
Asset removed or securely decommissioned
↓
8. Inventory Update
Status updated
Example Asset Inventory
| Asset ID | Asset Name | Type | Owner | Location | Classification | Criticality | Status |
|---|---|---|---|---|---|---|---|
| AST-001 | AWS Production | Cloud | CTO | AWS | Confidential | Critical | Active |
| AST-002 | Customer DB | Database | CTO | AWS | Restricted | Critical | Active |
| AST-003 | GitHub | SaaS | Engineering | Cloud | Confidential | Critical | Active |
| AST-004 | Employee Laptop | Hardware | IT | Employee | Confidential | High | Active |
| AST-005 | Corporate Website | Application | Marketing | Cloud | Public | Medium | Active |
The exact fields should be customized to the organization.
A.5.9 Audit Evidence
An auditor may look for evidence such as:
Information inventory
- Information asset register
- Data inventory
- Data classification records
- Data-flow diagrams
Technology inventory
- Hardware inventory
- Software inventory
- Application inventory
- Cloud asset inventory
- Network inventory
Ownership
- Asset owners
- Responsible departments
- RACI documentation
Lifecycle evidence
- Asset onboarding records
- Asset changes
- Asset retirement records
- Disposal records
Review evidence
- Periodic inventory review
- Reconciliation reports
- Asset-management reports
- Owner confirmation
A.5.9 Audit Checklist
| Audit Question | Evidence |
|---|---|
| Has the organization identified relevant information assets? | Information Asset Register |
| Has it identified associated technology assets? | Asset Inventory |
| Is an owner assigned to important assets? | Asset Register |
| Is information appropriately classified? | Classification Records |
| Are critical assets identified? | Criticality Assessment |
| Are cloud assets included? | Cloud Inventory |
| Are SaaS applications included? | SaaS Register |
| Are asset locations identified? | Asset Register |
| Is the inventory periodically reviewed? | Review Records |
| Are retired assets removed from the inventory? | Decommissioning Records |
| Are unauthorized or unknown assets investigated? | Security / IT Records |
| Is the inventory updated when new assets are introduced? | Change / Onboarding Records |
Common Mistakes
1. Maintaining only a laptop inventory
A.5.9 is much broader than an employee hardware list.
The organization should consider:
Information + Applications + Cloud + Infrastructure + Devices + Services
2. Forgetting SaaS applications
Employees may use dozens of cloud services.
Unknown SaaS applications can create security and compliance risks.
3. No asset ownership
An inventory should not simply say:
“AWS Production – Active.”
It should identify an appropriate owner.
4. Creating the inventory only for the audit
A spreadsheet created one week before the audit may quickly become outdated.
The inventory should be part of normal operational processes.
5. Not updating retired assets
Old systems, applications and accounts should not remain listed as active indefinitely.
6. Treating every asset equally
Critical production systems and public marketing documents do not require the same level of protection.
Asset criticality and information classification help prioritize security controls.
Practical Startup Implementation
A startup can implement A.5.9 without buying an expensive asset-management platform.
Start with five categories:
1. Information
Customer data, employee data, financial data, source code.
2. Applications
Production applications, internal applications and SaaS applications.
3. Cloud
AWS, Azure, GCP and associated resources.
4. Hardware
Laptops, servers and network equipment.
5. Third Parties
Important suppliers and services that process organizational information.
Then assign:
Owner → Classification → Criticality → Location → Status
Simple Rule
If you don’t know an asset exists, you cannot reliably assess its risk, protect it, monitor it or retire it.
Policy vs. Process vs. Evidence
| Element | Example |
|---|---|
| Policy | The organization shall maintain an inventory of information and associated assets relevant to information security. |
| Process | Assets are identified, assigned to owners, classified, recorded, periodically reviewed and updated throughout their lifecycle. |
| Evidence | Asset register, cloud inventory, application inventory, ownership records, classification records and periodic review evidence. |
The objective is not to create a massive spreadsheet.
The objective is to maintain a reliable picture of the organization’s information and technology environment.
Useful Resources
Recommended documents
- Information & Asset Inventory Template – [Insert Draft Document Link]
- Asset Classification Procedure – [Insert Draft Document Link]
- Asset Ownership Register – [Insert Draft Document Link]
- Cloud Asset Inventory – [Insert Draft Document Link]
- SaaS Application Register – [Insert Draft Document Link]
- Asset Lifecycle Management Procedure – [Insert Draft Document Link]
- Data Inventory Template – [Insert Draft Document Link]
Related ISO 27001 controls
A.5.9 can work closely with:
- A.5.1 – Policies for information security
- A.5.2 – Information security roles and responsibilities
- A.5.10 – Acceptable use of information and other associated assets
- A.5.11 – Return of assets
- A.5.12 – Classification of information
- A.5.13 – Labelling of information
- A.5.23 – Information security for use of cloud services
- A.7.9 – Security of assets off-premises
- A.8.1 – User endpoint devices
- A.8.9 – Configuration management
- A.8.10 – Information deletion
Final Takeaway
ISO 27001 Annex A 5.9 is about knowing what information and technology assets the organization has and ensuring they are properly identified, owned and managed.
A practical organization should be able to answer:
What information do we have?
Where is it stored?
Which systems process it?
Who owns those assets?
How sensitive or critical are they?
Are new and retired assets being tracked?
For startups, the approach can remain simple:
Identify → Register → Assign Owner → Classify → Assess Criticality → Protect → Review → Retire
The goal is not to maintain an inventory for the sake of ISO certification.
The goal is to ensure that the organization has a clear and current understanding of what it needs to protect.
